re:Invent 2017ã§ActiveDirectory on EC2ã«ã¤ãã¦ã®ã»ãã·ã§ã³ã«åå ããã®ã§ããã®å
容ããä¼ããã¾ãã
åæ
ActiveDirectory(以ä¸ãADã¨è¨è¼ããã) on EC2ã«è¨åããå 容ã¨ãªãã¾ãã(AWS DirectoryServiceã¯å¯¾è±¡å¤ã§ã)
AcitveDirectoryã¨ã¯
Active Directory ã¨ã¯ãã¤ã¯ãã½ããã«ãã£ã¦éçºããããªã³ãã¬ãã¹ã«ããããã£ã¬ã¯ããªã»ãµã¼ãã¹ã»ã·ã¹ãã ã§ãããWindows 2000 Serverããå°å ¥ããããã¦ã¼ã¶ã¨ã³ã³ãã¥ã¼ã¿ãªã½ã¼ã¹ã管çããã³ã³ãã¼ãã³ã群ã®ç·ç§°ã
主è¦ãªã³ã³ãã¼ãã³ã
- ãã¡ã¤ã³ ãµã¼ãã¹
- ãã§ãã¬ã¼ã·ã§ã³ãµã¼ãã¹
- 証ææ¸ãµã¼ãã¹
- Rights Management ãµã¼ãã¹
- Lightweight Directory ãµã¼ãã¹
ã»ãã·ã§ã³å 容
å°å ¥é¨å
ãªãADãéè¦ãªã®ã
ã»ã¦ã¼ã¶ã¼
ã»ãµã¼ãã¼
ã»ã¯ã©ã¤ã¢ã³ã
ã»ãããã¯ã¼ã¯ããã¤ã¹
ã»ã¢ããªã±ã¼ã·ã§ã³
ãªãAWSã§AD DSãå©ç¨ããã®ã
ã»AWSã®ã¨ã³ã¿ã¼ãã©ã¤ãºæ¡ç¨ãæ¡å¤§ãã¦ãã
ã»ã¯ã©ã¦ãå©ç¨ãæ®éã¨ãªã£ã
ã»ã¨ã³ã¿ã¼ãã©ã¤ãºä¼æ¥ã¯ADDSãå¿
è¦ã¨ããã¢ããªã±ã¼ã·ã§ã³ãå©ç¨ãã¦ãã
ã»AWSãå©ç¨ããADDSã¯ä½ãã¬ã¤ãã³ã·ã¼ã§ã¢ããªã±ã¼ã·ã§ã³ã«æ¥ç¶ã§ãã
AWSã«ADDSããããã¤ããããã®è¦³ç¹
ä¸è¬çãªè¦³ç¹
ã»ã«ã¹ã¿ãã¼ã¯ãããå½ã¦ãç£è¦ãããã¯ã¢ãããå¯ç¨æ§ã«è²¬ä»»ããã¤
ã»å¯ç¨æ§ãæ
ä¿ããããã«ãå°ãªãã¨ã2ã¤ã®AZã«ADDSãæ§ç¯ãã
ã»AZéã¯å¥ã®ãã¼ã¿ã¼ã»ã³ã¿ã¼ã®ããã«æ±ã
ã»ãã¥ãªãã£é¢ãã観ç¹
ã»ADã®ãã¹ããã©ã¯ãã£ã¹ã¯AWSã§ãã£ã¦ãé©ç¨ããã
ã»ãã¡ã¤ã³ã³ã³ããã¼ã©ã¼ã¸ã®ã¢ã¯ã»ã¹ãå¶å¾¡ãã
ã»ãã¡ã¤ã³ã³ã³ããã¼ã©ã¼ã¯ã¤ã³ã¿ã¼ãããããã®ã¢ã¯ã»ã¹ããããã¹ãã§ã¯ãªã
ãã»ãã¡ã¤ã³ã³ã³ããã¼ã©ã¼ã¨ã¤ã³ã¿ã¼ãããããã¢ã¯ã»ã¹ããªããµã¼ãã¼ã¯ãã©ã¤ãã¼ããµããããã«é
ç½®ãã
ã»NetworkACLã¨SecurityGroupãå©ç¨ããADã¸ã®ã©ã®ãã¼ãã解æ¾ãããå¶å¾¡ãã
ãããã¯ã¼ã¯ã«é¢ãã観ç¹
ã»ãããã¯ã¼ã¯ãããã¸
ã»ãããã¯ã¼ã¯ãç解ãã
ãã»ãã¤ããªããæ¥ç¶ã®å¿
è¦æ§
ãã»AWSDirectConnectãAWSVPNããããã¯æ¥ç¶ããªã
ã»è¤æ°ã®VPCãVPCãã¢ãªã³ã°æ¥ç¶ãããæ§æã®å ´åããã¡ã¤ã³ã³ã³ããã¼ã©ã¼ã¯ä¸ã¤ã®VPCã«æ§ç¯ããæ¹ãå¹ççã§ãããä»ã®VPCã«ããã¢ããªã±ã¼ã·ã§ã³ã¯ãVPCãã¢ãªã³ã°çµç±ã§ADã«æ¥ç¶ãããã¨ãã§ãã
IPã¢ãã¬ã¹ãDNSã«é¢ãã観ç¹
ã»äºåã«äºç´ãããã©ã¤ãã¼ãIPã¢ãã¬ã¹ãä»ä¸ãã
ã»ADã®ããã ãã«å¥åã®ãµãããããå®ç¾©ããããå
±éãµã¼ãã¹ãµããããã使ç¨ãã¦DCãå±éããã®ãä¸è¬çãªæ¹æ³ã§ã
ã»DCããã³DNSãµã¼ãã¼ã®å½¹å²ããã¹ããããµã¼ãã¼ã®ååã¨IPã¢ãã¬ã¹ã使ç¨ãã¦ãããã¯ã¼ã¯ããããã£ãæ§æãã
è¤æ°ãªã¼ã¸ã§ã³ã使ã£ããã¡ã¤ã³ã³ã³ããã¼ã©ã¼ãæ§ç¯ããéã®è¦³ç¹
ã»ãã¡ã¤ã³ã³ã³ããã¼ã©ã¼ã¯è¤æ°ã®ãªã¼ã¸ã§ã³ã®è¤æ°ã®AZã«ãããã¤ãã
ã»ADã®ã¬ã¤ãã³ã·ã¼ãæ¸ããããã«ãè¤æ°ã®ãªã¼ã¸ã§ã³ã¨ãã¼ã¿ã»ã³ã¿ã¼ãæ¥ç¶ã§ããããã«ãããã¨ãæ¨å¥¨ãã
ã»ä¸ç¶VPCãããã¯ãå¥ãªã¼ã¸ã§ã³ã®VPCã¯ãIPSecVPCã§æ¥ç¶ãã
ã»ããã¯ãã¼ã³ã¨ãã¦AWSã使ããããã¼ã¿ã»ã³ã¿ã¼ã使ããæ¤è¨ãã
AD DSè¨å®ã®è¦³ç¹
ã»ä¿¡é ¼é¢ä¿ã®ãªãå¥ã®ãã©ã¬ã¹ããå±éãã
ãã»ãªã¼ã¸ã§ã³éã§ADãæ¥ç¶ããå ´åã¯ãADã¬ããªã±ã¼ã·ã§ã³ãããã¦ããå¿
è¦ããã
ã»ãã§ãã¬ã¼ã·ã§ã³ã§æ°ãããã©ã¬ã¹ããä½æãã
ã»ã±ã«ããã¹èªè¨¼ã®ãã©ã¬ã¹ãä¿¡é ¼ã§æ°ãããã©ã¬ã¹ããä½æãã
ã»ã¬ããªã«DCãå±éãã¦ã³ã¼ãã¬ã¼ããã©ã¬ã¹ããæ¡å¼µãã
ã»åãã¡ã¤ã³ãããã¯ãåãã¡ã¤ã³ããªã¼ãå±éãã¦ã³ã¼ãã¬ã¼ããã©ã¬ã¹ããæ¡å¼µãã
ã°ãã¼ãã«ã«ã¿ãã°è¨å®ã®è¦³ç¹
ã»ã·ã³ã°ã«ãã¡ã¤ã³ãã©ã¬ã¹ãã®å ´åããã¹ã¦ã®ãã¡ã¤ã³ã³ã³ããã¼ã©ç¨ã«ã°ãã¼ãã«ã«ã¿ãã°ãä½æãã
ã»ãã«ããã¡ã¤ã³ãã©ã¬ã¹ãã®å ´åã以ä¸ã®ä¾å¤ãè¦ãã¦ãã¹ã¦ã®ãã¡ã¤ã³ã³ã³ããã¼ã©ç¨ã«ã°ãã¼ãã«ã«ã¿ãã°ãä½æãã
ãã»å¸¯åãéããã¦ãã
ãã»ã¤ã³ãã©ã¹ãã©ã¯ãã£æä½ãã¹ã¿ã¼ã®äºææ§ããªã
ãã¡ã¤ã³ã³ã³ãã©ã¼ã©ã¼ã¤ã³ã¹ãã¼ã«ã®è¦³ç¹
ã»EC2 for Windows ãèµ·åããPowerShellãããã¯ãDcPromo ã使ã£ã¦ãã¡ã¤ã³ã³ã³ããã¼ã©ãã¤ã³ã¹ãã¼ã«ãã
ã»ã¤ã³ãã¬ãã¹ã®ã¤ã¡ã¼ã¸ãVMã¤ã³ãã¼ããã
ã»ã¯ã¤ãã¯ã¹ã¿ã¼ããå©ç¨ãã
ãã»http://docs.aws.amazon.com/ja_jp/quickstart/latest/active-directory-ds/welcome.html
ADã®ããã¯ã¢ããããªã«ããªã¼ã®è¦³ç¹
ã»ADDSã®ããã¯ã¢ããã«ã¯ã¹ãããã·ã§ãããå©ç¨ããªã
ãã»ä¸è²«ãã¦ã¯ã©ãã·ã¥ããªã
ãã»VMIDã¯EC2ã§ã¯ããµãã¼ãããã¦ããªã
ã»Windowsããã¯ã¢ãããå©ç¨ãã
ã»ã·ã¹ãã ç¶æ
ã®ããã¯ã¢ããã®ããã«ãdedicated EBSãä½æãã
ãã»é·æéä¿æã®ããã«ãã·ã¹ãã ç¶æ
ããã¯ã¢ããã®ã¹ãããã·ã§ãããAmazonS3 ãããã¯ãAmazon Glacierã«ä¿åãã
Office 365ã¨ã®é£æºã®è¦³ç¹
ã»AD on EC2
ã»ADFS
ã»AD Sync
ã»AD Service Account
ã»Microsoft Azure AD Connect
AWSä¸ã§ã®ADDSãããã¤æ¹å¼
ã·ã³ã°ã«ãªã¼ã¸ã§ã³/ã·ã³ã°ã«VPC
ãã«ããªã¼ã¸ã§ã³/ãã«ãVPC
ã°ããã¼ãã«ãªãã¡ã¬ã³ã¹ã¢ã¼ããã¯ãã£
æå¾ã«
ã¨ã³ã¿ã¼ãã©ã¤ãºã®ã客æ§ãå¢ãã¦ããã®ã§ãActiveDirectoryãAWSã«æ§ç¯ããæ©ä¼ãä»å¾å¢ããã¨æãã¾ããActiveDirectoryãAWSã«æ§ç¯ããåºæ¬çãªèãæ¹ãéç´ããã¦ããã®ã§ããããåèã«ãªãã¾ãããre:inventã¯ã¾ã ã¾ã ç¶ãã¾ãã®ã§ãã¾ãã¬ãã¼ãæ¸ãããã¨æãã¾ãã